Report a vulnerability

Last updated: 30 September 2026


WBSO Aanvraag B.V. takes the security of its systems and of its clients' data seriously. Despite our care, a system can still contain a weakness. If you have found a vulnerability, we would like to hear about it so that we can fix it as quickly as possible.

This policy follows the Coordinated Vulnerability Disclosure guideline of the Dutch National Cyber Security Centre (NCSC, 2019). It applies to the website and portal at wbsoaanvraag.ai and to api.wbsoaanvraag.ai.

Reporting a vulnerability

Send your report by e-mail to security@wbsoaanvraag.ai, as soon as possible after you discover the vulnerability. Please include:

  • A description of the vulnerability
  • The steps we need to reproduce the issue
  • The affected URL, endpoint or part of the service
  • The potential impact: which data or functions are affected
  • Your contact details, so that we can reach you about the follow-up

You may report under a pseudonym. We can then only keep you informed if you give us an e-mail address where we can reach you.

Encryption is optional. If you want to send sensitive details encrypted, say so in a first message without those details, and we will agree with you on a secure way to transfer them.

What we commit to

  • We acknowledge receipt of your report within 3 working days.
  • Within 10 working days of receipt we send you our initial assessment, including an expected timeline for a fix.
  • We keep you informed of our progress until the issue is resolved.
  • We fix the vulnerability within a reasonable time, depending on its severity and complexity.
  • We treat your report as confidential and do not share your personal data with third parties without your consent, unless the law requires us to.
  • If you act in good faith and within the rules on this page, we will not report you to the police or take legal action against you.
  • If you wish, we will credit you by name as the person who found the vulnerability when we publish about it.

Rules for your research

When investigating our systems, please keep to the following rules:

  • Do not carry out denial-of-service attacks or other tests that generate large volumes of traffic.
  • Do not use social engineering or phishing against our staff, clients or suppliers.
  • Do not carry out physical attacks on offices, equipment or data centres.
  • Do not use automated scanners that put noticeable load on the service.
  • Do not view, modify or delete other people's data beyond the minimum needed to demonstrate the vulnerability. Do not copy or download other people's data; a screenshot is enough as proof.
  • Stop your research and report to us immediately as soon as you gain access to personal data.
  • Do not make changes to the system, install malware or a backdoor, or use brute force to gain access.
  • Delete any data you obtained during your research immediately after your report.
  • Do not disclose the vulnerability publicly or share it with others until it has been fixed or we have agreed a publication date together. Unless we agree otherwise, this period is at most 90 days from your report.

If you are unsure whether an action falls within these rules, contact us first at security@wbsoaanvraag.ai.

Out of scope

We do not treat the following as vulnerabilities under this policy:

  • Missing or non-standard security headers without demonstrated impact
  • Reports about the SPF, DKIM or DMARC configuration
  • Clickjacking on pages without sensitive actions
  • Self-XSS, where users can only affect themselves
  • Missing rate limiting on endpoints without sensitive actions
  • Output from automated tools without a working proof of concept
  • Test environments and previews, such as addresses on pages.dev
  • Vulnerabilities in third-party services we do not control. Please report those to the vendor concerned.

Rewards

We do not run a bug bounty programme, so a report does not entitle you to a financial reward. At our discretion, we may thank you for a report that helps us make the service more secure.

WBSO SUBSIDY

Curious if you qualify?

Do the WBSO Check